openocd
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/openocd_run.py
LOWAnomalyLOW
scripts/openocd_run.py
This module is primarily a CLI wrapper around OpenOCD for legitimate device programming/management, but it introduces a significant semantic command-execution risk by supporting action='raw' and forwarding user-provided --command strings directly into OpenOCD as '-c' commands when allowed by configuration. It also passes attacker-influenced cfg/search selections to OpenOCD via '-f'/'-s'. While there are no clear malware/exfiltration indicators in this fragment, the security risk is elevated for scenarios where an attacker can control CLI arguments or configuration inputs (impacting hardware integrity and enabling unintended OpenOCD behavior).
Confidence: 67%Severity: 52%
Audit Metadata